CVE-2022-23307

Related Vulnerabilities: CVE-2022-23307  

A flaw was found in the log4j 1.x chainsaw component, where the contents of certain log entries are deserialized and possibly permit code execution. This flaw allows an attacker to send a malicious request with serialized data to the server to be deserialized when the chainsaw component is run.

Description

A flaw was found in the log4j 1.x chainsaw component, where the contents of certain log entries are deserialized and possibly permit code execution. This flaw allows an attacker to send a malicious request with serialized data to the server to be deserialized when the chainsaw component is run.

Additional Information

  • Bugzilla 2041967: CVE-2022-23307 log4j: A deserialization flaw could lead to malicious code execution
  • CWE-502: Deserialization of Untrusted Data
  • FAQ: Frequently asked questions about CVE-2022-23307